CLICommand.java 16.7 KB
Newer Older
1 2 3
/*
 * The MIT License
 *
4
 * Copyright (c) 2004-2010, Sun Microsystems, Inc.
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
 *
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
 * in the Software without restriction, including without limitation the rights
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 * copies of the Software, and to permit persons to whom the Software is
 * furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice shall be included in
 * all copies or substantial portions of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
 * THE SOFTWARE.
 */
package hudson.cli;

26
import hudson.AbortException;
27 28
import hudson.Extension;
import hudson.ExtensionList;
29 30 31
import hudson.ExtensionPoint;
import hudson.cli.declarative.CLIMethod;
import hudson.ExtensionPoint.LegacyInstancesAreScopedToHudson;
32
import hudson.cli.declarative.OptionHandlerExtension;
33
import jenkins.model.Jenkins;
34 35
import hudson.remoting.Callable;
import hudson.remoting.Channel;
36
import hudson.remoting.ChannelProperty;
37
import hudson.security.CliAuthenticator;
38
import hudson.security.SecurityRealm;
39 40 41
import org.acegisecurity.Authentication;
import org.acegisecurity.context.SecurityContext;
import org.acegisecurity.context.SecurityContextHolder;
42 43 44 45 46
import org.apache.commons.discovery.ResourceClassIterator;
import org.apache.commons.discovery.ResourceNameIterator;
import org.apache.commons.discovery.resource.ClassLoaders;
import org.apache.commons.discovery.resource.classes.DiscoverClasses;
import org.apache.commons.discovery.resource.names.DiscoverServiceNames;
47 48
import org.jvnet.hudson.annotation_indexer.Index;
import org.jvnet.tiger_types.Types;
49
import org.kohsuke.args4j.ClassParser;
50
import org.kohsuke.args4j.CmdLineException;
51
import org.kohsuke.args4j.CmdLineParser;
52
import org.kohsuke.args4j.spi.OptionHandler;
53

K
kohsuke 已提交
54
import java.io.BufferedInputStream;
55
import java.io.IOException;
56 57
import java.io.InputStream;
import java.io.PrintStream;
58
import java.lang.reflect.Type;
59 60
import java.nio.charset.Charset;
import java.nio.charset.UnsupportedCharsetException;
61
import java.util.List;
K
kohsuke 已提交
62
import java.util.Locale;
63
import java.util.logging.Level;
64
import java.util.logging.Logger;
65 66 67 68

/**
 * Base class for Hudson CLI.
 *
K
kohsuke 已提交
69
 * <h2>How does a CLI command work</h2>
70
 * <p>
K
kohsuke 已提交
71
 * The users starts {@linkplain CLI the "CLI agent"} on a remote system, by specifying arguments, like
72
 * <tt>"java -jar jenkins-cli.jar command arg1 arg2 arg3"</tt>. The CLI agent creates
K
kohsuke 已提交
73 74
 * a remoting channel with the server, and it sends the entire arguments to the server, along with
 * the remoted stdin/out/err.
75 76
 *
 * <p>
K
kohsuke 已提交
77
 * The Hudson master then picks the right {@link CLICommand} to execute, clone it, and
78
 * calls {@link #main(List, Locale, InputStream, PrintStream, PrintStream)} method.
K
kohsuke 已提交
79 80
 *
 * <h2>Note for CLI command implementor</h2>
K
Kohsuke Kawaguchi 已提交
81
 * Start with <a href="http://wiki.jenkins-ci.org/display/JENKINS/Writing+CLI+commands">this document</a>
K
kohsuke 已提交
82 83
 * to get the general idea of CLI.
 *
K
kohsuke 已提交
84 85 86 87 88
 * <ul>
 * <li>
 * Put {@link Extension} on your implementation to have it discovered by Hudson.
 *
 * <li>
89
 * Use <a href="http://args4j.dev.java.net/">args4j</a> annotation on your implementation to define
K
kohsuke 已提交
90
 * options and arguments (however, if you don't like that, you could override
91
 * the {@link #main(List, Locale, InputStream, PrintStream, PrintStream)} method directly.
92
 *
K
kohsuke 已提交
93 94 95 96 97 98 99 100
 * <li>
 * stdin, stdout, stderr are remoted, so proper buffering is necessary for good user experience.
 *
 * <li>
 * Send {@link Callable} to a CLI agent by using {@link #channel} to get local interaction,
 * such as uploading a file, asking for a password, etc.
 *
 * </ul>
101 102 103
 *
 * @author Kohsuke Kawaguchi
 * @since 1.302
104
 * @see CLIMethod
105
 */
106
@LegacyInstancesAreScopedToHudson
107 108 109 110 111 112
public abstract class CLICommand implements ExtensionPoint, Cloneable {
    /**
     * Connected to stdout and stderr of the CLI agent that initiated the session.
     * IOW, if you write to these streams, the person who launched the CLI command
     * will see the messages in his terminal.
     *
K
kohsuke 已提交
113
     * <p>
114 115 116
     * (In contrast, calling {@code System.out.println(...)} would print out
     * the message to the server log file, which is probably not what you want.
     */
117
    public transient PrintStream stdout,stderr;
118

K
kohsuke 已提交
119 120 121 122 123 124
    /**
     * Connected to stdin of the CLI agent.
     *
     * <p>
     * This input stream is buffered to hide the latency in the remoting.
     */
125
    public transient InputStream stdin;
K
kohsuke 已提交
126

127 128 129
    /**
     * {@link Channel} that represents the CLI JVM. You can use this to
     * execute {@link Callable} on the CLI JVM, among other things.
K
Kohsuke Kawaguchi 已提交
130 131 132 133
     *
     * <p>
     * Starting 1.445, CLI transports are not required to provide a channel
     * (think of sshd, telnet, etc), so in such a case this field is null.
134
     */
135
    public transient Channel channel;
136

137 138 139
    /**
     * The locale of the client. Messages should be formatted with this resource.
     */
140
    public transient Locale locale;
141

K
Kohsuke Kawaguchi 已提交
142 143 144 145 146
    /**
     * Set by the caller of the CLI system if the transport already provides
     * authentication. Due to the compatibility issue, we still allow the user
     * to use command line switches to authenticate as other users.
     */
147
    private transient Authentication transportAuth;
148 149 150 151 152 153 154 155 156 157 158 159 160 161

    /**
     * Gets the command name.
     *
     * <p>
     * For example, if the CLI is invoked as <tt>java -jar cli.jar foo arg1 arg2 arg4</tt>,
     * on the server side {@link CLICommand} that returns "foo" from {@link #getName()}
     * will be invoked.
     *
     * <p>
     * By default, this method creates "foo-bar-zot" from "FooBarZotCommand".
     */
    public String getName() {
        String name = getClass().getName();
162
        name = name.substring(name.lastIndexOf('.') + 1); // short name
163
        name = name.substring(name.lastIndexOf('$')+1);
164 165 166 167
        if(name.endsWith("Command"))
            name = name.substring(0,name.length()-7); // trim off the command

        // convert "FooBarZot" into "foo-bar-zot"
K
kohsuke 已提交
168 169
        // Locale is fixed so that "CreateInstance" always become "create-instance" no matter where this is run.
        return name.replaceAll("([a-z0-9])([A-Z])","$1-$2").toLowerCase(Locale.ENGLISH);
170 171
    }

K
kohsuke 已提交
172 173 174 175 176 177
    /**
     * Gets the quick summary of what this command does.
     * Used by the help command to generate the list of commands.
     */
    public abstract String getShortDescription();

178
    public int main(List<String> args, Locale locale, InputStream stdin, PrintStream stdout, PrintStream stderr) {
K
kohsuke 已提交
179
        this.stdin = new BufferedInputStream(stdin);
180 181
        this.stdout = stdout;
        this.stderr = stderr;
182
        this.locale = locale;
183
        registerOptionHandlers();
184
        CmdLineParser p = new CmdLineParser(this);
185 186 187 188 189

        // add options from the authenticator
        SecurityContext sc = SecurityContextHolder.getContext();
        Authentication old = sc.getAuthentication();

190
        CliAuthenticator authenticator = Jenkins.getInstance().getSecurityRealm().createCliAuthenticator(this);
191
        new ClassParser().parse(authenticator,p);
192

193 194
        try {
            p.parseArgument(args.toArray(new String[args.size()]));
195
            Authentication auth = authenticator.authenticate();
196
            if (auth==Jenkins.ANONYMOUS)
197 198
                auth = loadStoredAuthentication();
            sc.setAuthentication(auth); // run the CLI with the right credential
199
            if (!(this instanceof LoginCommand || this instanceof HelpCommand))
200
                Jenkins.getInstance().checkPermission(Jenkins.READ);
201 202 203 204 205
            return run();
        } catch (CmdLineException e) {
            stderr.println(e.getMessage());
            printUsage(stderr, p);
            return -1;
206 207 208 209
        } catch (AbortException e) {
            // signals an error without stack trace
            stderr.println(e.getMessage());
            return -1;
210 211 212
        } catch (Exception e) {
            e.printStackTrace(stderr);
            return -1;
213 214
        } finally {
            sc.setAuthentication(old); // restore
215 216 217
        }
    }

218
    /**
219 220
     * Loads the persisted authentication information from {@link ClientAuthenticationCache}
     * if the current transport provides {@link Channel}.
221 222 223
     */
    protected Authentication loadStoredAuthentication() throws InterruptedException {
        try {
224 225
            if (channel!=null)
                return new ClientAuthenticationCache(channel).get();
226 227 228 229
        } catch (IOException e) {
            stderr.println("Failed to access the stored credential");
            e.printStackTrace(stderr);  // recover
        }
230
        return Jenkins.ANONYMOUS;
231 232
    }

233 234 235 236 237 238 239 240 241 242 243 244 245 246
    /**
     * Determines if the user authentication is attempted through CLI before running this command.
     *
     * <p>
     * If your command doesn't require any authentication whatsoever, and if you don't even want to let the user
     * authenticate, then override this method to always return false &mdash; doing so will result in all the commands
     * running as anonymous user credential.
     *
     * <p>
     * Note that even if this method returns true, the user can still skip aut 
     *
     * @param auth
     *      Always non-null.
     *      If the underlying transport had already performed authentication, this object is something other than
247
     *      {@link jenkins.model.Jenkins#ANONYMOUS}.
248 249
     */
    protected boolean shouldPerformAuthentication(Authentication auth) {
250
        return auth== Jenkins.ANONYMOUS;
251 252
    }

253 254 255 256 257 258 259 260 261 262 263 264 265 266
    /**
     * Returns the identity of the client as determined at the CLI transport level.
     *
     * <p>
     * When the CLI connection to the server is tunneled over HTTP, that HTTP connection
     * can authenticate the client, just like any other HTTP connections to the server
     * can authenticate the client. This method returns that information, if one is available.
     * By generalizing it, this method returns the identity obtained at the transport-level authentication.
     *
     * <p>
     * For example, imagine if the current {@link SecurityRealm} is doing Kerberos authentication,
     * then this method can return a valid identity of the client.
     *
     * <p>
267
     * If the transport doesn't do authentication, this method returns {@link jenkins.model.Jenkins#ANONYMOUS}.
268 269
     */
    public Authentication getTransportAuthentication() {
270
        Authentication a = transportAuth; 
271
        if (a==null)    a = Jenkins.ANONYMOUS;
272 273 274
        return a;
    }

275 276 277 278
    public void setTransportAuth(Authentication transportAuth) {
        this.transportAuth = transportAuth;
    }

279 280 281 282 283
    /**
     * Executes the command, and return the exit code.
     *
     * @return
     *      0 to indicate a success, otherwise an error code.
284 285 286 287 288 289
     * @throws AbortException
     *      If the processing should be aborted. Hudson will report the error message
     *      without stack trace, and then exits this command.
     * @throws Exception
     *      All the other exceptions cause the stack trace to be dumped, and then
     *      the command exits with an error code.
290
     */
291
    protected abstract int run() throws Exception;
292 293

    protected void printUsage(PrintStream stderr, CmdLineParser p) {
294
        stderr.println("java -jar jenkins-cli.jar "+getName()+" args...");
295
        printUsageSummary(stderr);
296 297 298
        p.printUsage(stderr);
    }

299 300 301 302 303 304 305 306 307
    /**
     * Called while producing usage. This is a good method to override
     * to render the general description of the command that goes beyond
     * a single-line summary. 
     */
    protected void printUsageSummary(PrintStream stderr) {
        stderr.println(getShortDescription());
    }

308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328
    /**
     * Convenience method for subtypes to obtain the system property of the client.
     */
    protected String getClientSystemProperty(String name) throws IOException, InterruptedException {
        return channel.call(new GetSystemProperty(name));
    }

    private static final class GetSystemProperty implements Callable<String, IOException> {
        private final String name;

        private GetSystemProperty(String name) {
            this.name = name;
        }

        public String call() throws IOException {
            return System.getProperty(name);
        }

        private static final long serialVersionUID = 1L;
    }

329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346
    protected Charset getClientCharset() throws IOException, InterruptedException {
        String charsetName = channel.call(new GetCharset());
        try {
            return Charset.forName(charsetName);
        } catch (UnsupportedCharsetException e) {
            LOGGER.log(Level.FINE,"Server doesn't have charset "+charsetName);
            return Charset.defaultCharset();
        }
    }

    private static final class GetCharset implements Callable<String, IOException> {
        public String call() throws IOException {
            return Charset.defaultCharset().name();
        }

        private static final long serialVersionUID = 1L;
    }

K
Kohsuke Kawaguchi 已提交
347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367
    /**
     * Convenience method for subtypes to obtain environment variables of the client.
     */
    protected String getClientEnvironmentVariable(String name) throws IOException, InterruptedException {
        return channel.call(new GetEnvironmentVariable(name));
    }

    private static final class GetEnvironmentVariable implements Callable<String, IOException> {
        private final String name;

        private GetEnvironmentVariable(String name) {
            this.name = name;
        }

        public String call() throws IOException {
            return System.getenv(name);
        }

        private static final long serialVersionUID = 1L;
    }

368 369 370 371 372 373 374 375 376 377 378 379 380
    /**
     * Creates a clone to be used to execute a command.
     */
    protected CLICommand createClone() {
        try {
            return getClass().newInstance();
        } catch (IllegalAccessException e) {
            throw new AssertionError(e);
        } catch (InstantiationException e) {
            throw new AssertionError(e);
        }
    }

381 382 383 384 385
    /**
     * Auto-discovers {@link OptionHandler}s and add them to the given command line parser.
     */
    protected void registerOptionHandlers() {
        try {
386
            for (Class c : Index.list(OptionHandlerExtension.class, Jenkins.getInstance().pluginManager.uberClassLoader,Class.class)) {
387 388 389 390 391 392 393
                Type t = Types.getBaseClass(c, OptionHandler.class);
                CmdLineParser.registerHandler(Types.erasure(Types.getTypeArgument(t,0)), c);
            }
        } catch (IOException e) {
            throw new Error(e);
        }
    }
394

395 396 397 398
    /**
     * Returns all the registered {@link CLICommand}s.
     */
    public static ExtensionList<CLICommand> all() {
399
        return Jenkins.getInstance().getExtensionList(CLICommand.class);
400 401 402 403 404 405
    }

    /**
     * Obtains a copy of the command for invocation.
     */
    public static CLICommand clone(String name) {
406 407 408
        for (CLICommand cmd : all())
            if(name.equals(cmd.getName()))
                return cmd.createClone();
409 410
        return null;
    }
411 412

    private static final Logger LOGGER = Logger.getLogger(CLICommand.class.getName());
J
jpederzolli 已提交
413

414 415 416 417 418
    /**
     * Key for {@link Channel#getProperty(Object)} that links to the {@link Authentication} object
     * which captures the identity of the client given by the transport layer.
     */
    public static final ChannelProperty<Authentication> TRANSPORT_AUTHENTICATION = new ChannelProperty<Authentication>(Authentication.class,"transportAuthentication");
419 420 421 422 423 424 425 426 427 428 429 430 431 432 433

    private static final ThreadLocal<CLICommand> CURRENT_COMMAND = new ThreadLocal<CLICommand>();

    /*package*/ static CLICommand setCurrent(CLICommand cmd) {
        CLICommand old = getCurrent();
        CURRENT_COMMAND.set(cmd);
        return old;
    }

    /**
     * If the calling thread is in the middle of executing a CLI command, return it. Otherwise null.
     */
    public static CLICommand getCurrent() {
        return CURRENT_COMMAND.get();
    }
434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450

    static {
        // register option handlers that are defined
        ClassLoaders cls = new ClassLoaders();
        cls.put(Jenkins.getInstance().getPluginManager().uberClassLoader);

        ResourceNameIterator servicesIter =
            new DiscoverServiceNames(cls).findResourceNames(OptionHandler.class.getName());
        final ResourceClassIterator itr =
            new DiscoverClasses(cls).findResourceClasses(servicesIter);

        while(itr.hasNext()) {
            Class h = itr.nextResourceClass().loadClass();
            Class c = Types.erasure(Types.getTypeArgument(Types.getBaseClass(h, OptionHandler.class), 0));
            CmdLineParser.registerHandler(c,h);
        }
    }
451
}